There was a time when the phrase "AI-powered cyberattack" still sounded like marketing. Vendors said it on stage, conferences nodded along, threat reports hinted at it — but if you pressed a researcher for specifics, you usually got a shrug and a slide deck about the future.
That future arrived this year, and it looks nothing like a sci-fi movie. No sentient machines, no Skynet. Instead, it looks an awful lot like a software marketplace: pricing tiers, support channels, update cadences, even customer reviews — except the product is offensive hacking capability, and the customers are criminals.
That's the takeaway from a fresh report by Trellix's Advanced Research Center, which spent the first half of 2026 monitoring underground forums, Telegram channels, and dark web markets. The conclusion is blunt: AI has moved from the edges of criminal tooling to its operational core. Threat actors aren't talking about AI anymore. They're selling it.
This isn't a headline — it's a structural shift. Here's what's actually for sale, why it matters, and what it means for the rest of us.
The most striking thing about Trellix's findings is how professional these offerings look. Take APEX AI, advertised on DarkForums by an actor called Shadowx007. It's marketed as a self-hosted, uncensored offensive AI tool, positioned to deliver "APT-grade attack planning" — nation-state-level capability, sold as a product. No ethics, no guardrails, and apparently a full sales pitch to go with it.
Then there's Metamorphic Crypter, sold on the Exploit forum by an actor called ImpactSolutions. Crypter services are old news — they've helped malware dodge antivirus for years. What's new is the AI twist: the seller claims the tool generates unique, per-build malware variations that signature-based detection simply can't keep up with, and that even Windows Defender can't catch it. Whether the claim holds doesn't really matter. The point is the market has moved on, and signature-based defenses were already struggling before AI started doing the heavy lifting.
BreachForums, meanwhile, hosts MessiahGPT — an AI model pitched as having "zero ethical constraints," the polar opposite of the carefully guarded commercial models most of us use every day. Over on Telegram, Russian-speaking criminal communities are being served by DarkGPT, which advertises itself as a 24/7 assistant for "darknet projects," promising unrestricted code and exploit writing — with three free queries to get you hooked.
Free trials. In a hacking tool. That's how far the commercialization has gone.
The tools are only half the story. Trellix also documented a secondary market for stolen AI credentials — session cookies and API access to models like Claude and GPT, resold on forums at prices as low as 65% below official API rates.
In plain terms: criminals are piggybacking on legitimate accounts to run their attacks, which makes everything much harder to trace. Defenders can't just watch for "suspicious" logins anymore, because the logins look perfectly normal. They belong to real users.
And here's one that should make HR departments nervous: Trellix found an AI-assisted interview cheating tool, built in Rust and engineered to be invisible during screen shares, so candidates can quietly use AI through technical interviews. It's a strange detail in a report full of scary ones, but it's a reminder that this stuff isn't just about malware. It's about attacking every layer of trust an organization runs on.
This isn't a blip. Halcyon's analysis of 20 dark-web forums and five underground markets counted just 38 posts about AI utilities in December 2025. By February 2026, that number had jumped to 1,486. A roughly 39x increase in two months.
Google's Threat Intelligence Group has gone further, identifying malware families like PROMPTFLUX and PROMPTSTEAL that actually call LLMs while running — generating scripts on the fly and obfuscating their own code in real time. And the pricing tells you everything about the target audience: AI-generated ransomware kits have been observed selling for $400 to $1,200 apiece. Weaponized prompt-injection templates, pre-built and embedded in PDFs, emails, and calendar invites, go for about $150 a month — less than a streaming bundle.
Strip away the jargon, and here's the uncomfortable truth: the barrier to entry for serious cybercrime just collapsed. You no longer need to be a gifted developer to plan an intrusion, write evasive malware, or run phishing at scale. You need a budget and a Telegram account.
For defenders, the implications are structural:
Signature-based detection is becoming a rear-guard action. When malware is unique on every build, "seen it before" stops being a useful test. Behavioral detection isn't a best practice anymore — it's a survival requirement.
Identity is the new perimeter. Treat "authorized" sessions showing bot-like behavior — odd locations, unusual devices, absurd query volumes — as compromised until proven otherwise.
Incident response needs a new chapter. Attacks that run on stolen legitimate credentials look authorized, because in a sense they are.
Hiring controls need redesigning. If AI can quietly pass a technical interview for a candidate, every control that assumed a human was doing the thinking needs a second look.
Here's the honest take: the underground industrialized AI faster than most enterprises industrialized AI defense. That gap is real, it's widening, and no single tool will close it. What closes it is boring, unglamorous work — behavioral monitoring, credential hygiene, conditional access, reading the underground forums yourself, and accepting that manual response times can't match machine speed.
The adversaries are running a SaaS business now. Defenders need to stop acting like it's still 2019.
If there's one thing to take away, it's this: the "AI hacker" story stopped being science fiction sometime in the last six months, and the people selling it treat it like any other subscription. The question is no longer whether attackers will use AI. It's whether defenders will use theirs.
What's your take — is your organization ready for AI-speed attacks, or is the industry still catching up? Drop your thoughts in the comments.
Sources: